QuestionQ85
Cortex XSOARWhich action should an administrator take to create automated response actions when a user account is compromised, allowing an attacker to upload data to an external IP address and infect a machine on the company network with malware?
- A Create automation rules in Cortex XDR that will trigger for each alert.
- B Create a script in Cortex XSOAR that will run a playbook based on the scenario.
- C Create playbook triggers in Cortex XSIAM and run playbooks for each alert.
- D Map the events as type of Cortex XSOAR incident, then run a playbook.
Community Discussion